← SonarQubeCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to SonarQube
Snapshot Sep 30, 2026 · 23:13 UTC · version 2.6.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "sonar-integrate",
"description": "Installs sonarqube-cli if not already installed, authenticates, and integrates SonarQube with the current agent (installs analysis hooks & SonarQube MCP Server). Use when the user wants to set up SonarQube integration or asks to configure SonarQube.",
"included_files": [],
"skill_md_contents": "---\nname: sonar-integrate\ndescription: \"Installs sonarqube-cli if not already installed, authenticates, and integrates SonarQube with the current agent (installs analysis hooks & SonarQube MCP Server). Use when the user wants to set up SonarQube integration or asks to configure SonarQube.\"\nallowed-tools: Bash(which:*), Bash(Get-Command:*), Bash(sonar:*), Bash(agy:*), Bash(curl:*), Bash(irm:*), Bash(iex:*), Bash(brew:*), Bash(mise:*), Bash(docker ps:*), Bash(podman ps:*), Bash(nerdctl ps:*)\n---\n\n# Integrate SonarQube\n\nGuide the user through installing **sonarqube-cli** (if needed), **updating it to the latest version** when already installed, authenticating, and completing agent-specific integration. Assume SonarQube itself is already set up; this skill only wires the assistant.\n\n## Instructions\n\nInteraction rule: for every finite decision, always present predefined selector options (single-choice or multi-choice as appropriate) instead of asking for free-form text. If the user gives an invalid answer, re-show the same selector.\n\n### Step 1 — Check for sonarqube-cli and update it\n\nCheck if `sonar` is available on the PATH by running `which sonar` (macOS/Linux) or `Get-Command sonar` (Windows) yourself.\n\n**If found:** first determine how it was installed, because the upgrade path differs:\n\n- **Managed by a package or version manager** (e.g. installed via Homebrew or mise — the binary lives under the manager's prefix rather than `~/.local/share/sonarqube-cli/bin`): do **not** run `sonar self-update`, as it conflicts with the manager. Run the manager's upgrade command yourself instead (Homebrew: `brew upgrade --cask sonarqube-cli`; mise: `mise upgrade aqua:SonarSource/sonarqube-cli`), then go to Step 2. If the upgrade fails, show the output but **still continue** to Step 2 as long as `sonar` remains usable.\n- **Installed via the shell/PowerShell script, or unsure:** run **`sonar self-update`** yourself and wait for it to finish.\n - **If it succeeds:** briefly tell the user the CLI is up to date (or was upgraded), then go to Step 2.\n - **If it fails:** show the relevant output, suggest they run `sonar self-update` manually (e.g. offline or network issues), then **still continue** to Step 2 if `sonar` remains usable — do not block the rest of the flow unless the binary is missing or broken.\n\n**If not found:** pick an install command from the table below, show it to the user, and ask for explicit confirmation **before running it**. Do **not** execute the command until the user confirms.\n\nThe shell/PowerShell script is the default and works everywhere. If the user already manages CLIs with **Homebrew** or **mise**, prefer that route so future upgrades stay managed by the tool — the Step 1 update above then defers to the manager.\n\n| Platform / method | Install command |\n| ------------------------ | ------------------------------------------------------------------------------------------------------------------------ |\n| macOS / Linux (script) | `curl -o- https://raw.githubusercontent.com/SonarSource/sonarqube-cli/refs/heads/master/user-scripts/install.sh \\| bash` |\n| macOS / Linux (Homebrew) | `brew install --cask sonarqube-cli` |\n| Any OS (mise) | `mise use -g aqua:SonarSource/sonarqube-cli` |\n| Windows (PowerShell) | `irm https://raw.githubusercontent.com/SonarSource/sonarqube-cli/refs/heads/master/user-scripts/install.ps1 \\| iex` |\n\n**If the user confirms:** run the command yourself using a shell command. After it finishes, re-run the PATH check (`which sonar` or `Get-Command sonar`) yourself to verify before continuing.\n\n**If the user declines:** stop the skill and ask the user to install `sonarqube-cli` manually and then re-invoke the sonar-integrate skill.\n\n---\n\n### Step 2 — Check authentication status\n\nRun `sonar auth status` yourself using a shell command.\n\n**If already authenticated:** note the connected server and organisation from the output,\nthen skip directly to Step 4.\n\n**If not authenticated:** proceed to Step 3.\n\n---\n\n### Step 3 — Authenticate (`sonar auth login`)\n\nThis step requires user interaction — do **not** run it yourself.\n\nFirst determine the connection type using a single-choice selector with these options:\n\n1. SonarQube Cloud - EU (default)\n2. SonarQube Cloud - US\n3. Self-hosted SonarQube Server\n\nDo not ask an open-ended text question for this decision.\n\nCollect:\n\n| Scenario | Information needed |\n| ------------------------------ | ------------------------------------------------------------- |\n| SonarQube Cloud — EU (default) | organization key (e.g. `my-org`) |\n| SonarQube Cloud — US | organization key + confirm US region (`https://sonarqube.us`) |\n| SonarQube Server | server URL (e.g. `https://sonarqube.yourcompany.com`) |\n\nBuild the login command and show it to the user:\n\n| Scenario | Command |\n| -------------------- | ------------------------------------------------------- |\n| SonarQube Cloud — EU | `sonar auth login -o <org-key>` |\n| SonarQube Cloud — US | `sonar auth login -o <org-key> -s https://sonarqube.us` |\n| SonarQube Server | `sonar auth login -s <server-url>` |\n\nTell the user:\n\n> \"Run the command below — it will open your browser to log in. The token is stored\n> securely in your system keychain and never appears in this chat.\"\n\nWait for the user to confirm they logged in, then run `sonar auth status` yourself to\nverify before continuing.\n\n---\n\n### Step 4 — Agent-specific integration\n\n> **Container runtime requirement:** The SonarQube MCP Server runs inside a container, started via `sonar run mcp` (which detects Docker, Podman, or Nerdctl). A container runtime must be **installed and running** for the MCP tools to load — otherwise integration can complete successfully yet no `mcp__sonarqube__*` tools appear in the session. **Verify this yourself:** run `docker ps` (falling back to `podman ps` / `nerdctl ps`). If one succeeds, the runtime is up — proceed. If none do, tell the user their container runtime is not running and ask them to start it, then note they must restart the agent session afterward for the tools to load (starting the daemon and restarting the session are the only parts you cannot do for them).\n\nPick exactly one branch below based on which agent you are. Do not run the other branches.\n\n- Claude Code -> **4.a**\n- Copilot CLI -> **4.b**\n- Codex -> **4.c**\n- Cursor -> **4.d**\n- Antigravity -> **4.e**\n- Gemini CLI -> **4.f**\n\n#### 4.a — Claude Code (`sonar integrate claude`)\n\nRun **`sonar integrate claude`**, which configures the **SonarQube MCP Server**, **secrets-scanning hooks**, and any other supported integration the CLI applies.\n\nIt wires **MCP** (for skills like sonar-quality-gate, sonar-analyze, sonar-coverage, sonar-duplication, sonar-dependency-risks) and **secrets-scanning hooks** into the user’s Claude Code config. When available, SonarQube Vortex analysis hooks are also installed.\n\nAsk the user using a single-choice selector with these options:\n\n1. Current project only (default)\n2. Global (all projects)\n\nDo not ask an open-ended text question for this decision.\n\nThen run the appropriate command yourself using a shell command, and adding `--non-interactive`:\n\n| Scenario | Command |\n| ------------ | --------------------------------------------------- |\n| Project-only | `sonar integrate claude --non-interactive` |\n| Global | `sonar integrate claude --global --non-interactive` |\n\n#### 4.b — Copilot CLI (`sonar integrate copilot`)\n\nRun **`sonar integrate copilot`**, which configures the **SonarQube MCP Server**, **secrets-scanning hooks**, and any other supported integration the CLI applies.\n\nIt wires **MCP** (for skills like sonar-quality-gate, sonar-analyze, sonar-coverage, sonar-duplication, sonar-dependency-risks) and **secrets-scanning hooks** into the user’s Copilot CLI config.\n\nAsk the user using a single-choice selector with these options:\n\n1. Current project only (default)\n2. Global (all projects)\n\nDo not ask an open-ended text question for this decision.\n\nThen run the appropriate command yourself using a shell command, and adding `--non-interactive`:\n\n| Scenario | Command |\n| ------------ | --------------------------------------------------- |\n| Project-only | `sonar integrate copilot --non-interactive` |\n| Global | `sonar integrate copilot --global --non-interactive` |\n\n#### 4.c — Codex (`sonar integrate codex`)\n\nRun **`sonar integrate codex`**, which configures the **SonarQube MCP Server**, **secrets-scanning hooks**, and—when your SonarQube Cloud org has Vortex analysis—a **PostToolUse** hook on **`apply_patch`** that surfaces findings inline after edits.\n\nAsk the user using a single-choice selector with these options:\n\n1. Current project only (default)\n2. Global (all projects)\n\nDo not ask an open-ended text question for this decision.\n\nThen run the appropriate command yourself using a shell command, and adding `--non-interactive`:\n\n| Scenario | Command |\n| ------------ | -------------------------------------------------- |\n| Project-only | `sonar integrate codex --non-interactive` |\n| Global | `sonar integrate codex --global --non-interactive` |\n\nIf the project key is not already known from `sonar-project.properties` or prior context, add **`--project <key>`** to the project-only command.\n\n#### 4.d — Cursor (`sonar integrate cursor`)\n\nRun **`sonar integrate cursor`**, which configures **secrets-scanning hooks** (`beforeSubmitPrompt`, `beforeReadFile`, and `preToolUse`), **MCP**, **Context Augmentation** (when entitled), and **Vortex analysis instructions** (when entitled, project scope only).\n\nAsk the user using a single-choice selector with these options:\n\n1. Current project only (default)\n2. Global (all projects)\n\nDo not ask an open-ended text question for this decision.\n\nThen run the appropriate command yourself using a shell command, adding **`--non-interactive`**:\n\n| Scenario | Command |\n| ------------ | ------------------------------------------------------ |\n| Project-only | `sonar integrate cursor --non-interactive` |\n| Global | `sonar integrate cursor --global --non-interactive` |\n\nIf the project key is not already known from `sonar-project.properties` or prior context, add **`--project <key>`** to the project-only command.\n\nAfter integrate completes, tell the user to enable the MCP server manually in Cursor: open **Settings → MCP**, find the `sonarqube` entry, and toggle it on. Also tell the user to ensure a container runtime (Docker, Podman, or Nerdctl) is running. A Cursor session restart may be needed for the tools to appear.\n\n#### 4.e — Antigravity (`sonar integrate antigravity`)\n\nRun **`sonar integrate antigravity`**, which configures **secrets-scanning hooks**, **prompt-secrets and Vortex analysis instructions**, **Context Augmentation** (when entitled), and **MCP** in the Antigravity harness.\n\nAsk the user using a single-choice selector with these options:\n\n1. Current project only (default)\n2. Global (all projects)\n\nDo not ask an open-ended text question for this decision.\n\nThen run the appropriate command yourself using a shell command, adding **`--non-interactive`**:\n\n| Scenario | Command |\n| ------------ | ------------------------------------------------------ |\n| Project-only | `sonar integrate antigravity --non-interactive` |\n| Global | `sonar integrate antigravity --global --non-interactive` |\n\nIf the project key is not already known from `sonar-project.properties` or prior context, add **`--project <key>`** to the project-only command.\n\nTell the user to ensure a container runtime (Docker, Podman, or Nerdctl) is running, and to restart the Antigravity session if MCP tools do not appear after integrate completes.\n\n#### 4.f — Gemini CLI *(legacy)*\n\nGemini CLI starts the SonarQube MCP Server via `sonar run mcp`, which handles container runtime detection (Docker, Podman, Nerdctl) and authentication automatically. Authentication was handled in Steps 2–3.\n\nConfirm that integration is ready — the MCP server will start automatically when Gemini CLI reads **`gemini-extension.json`**.\n\nRecommend migrating to **Antigravity** (**4.e**): run **`agy plugin import gemini`**, then **`sonar integrate antigravity`**. Gemini CLI did not support SonarQube hooks or Vortex analysis wiring.\n\n---\n\n### Summary message\n\nAfter all steps complete, print a summary:\n\n```\n✅ SonarQube integration is ready.\n\n sonarqube-cli: up to date\n Authentication: token stored in system keychain\n MCP Server: configured (ensure a container runtime (Docker, Podman, or Nerdctl) is running, then restart the agent session if tools do not appear)\n\nYou can verify at any time with: sonar auth status\nTo refresh CLI + wiring later: invoke the sonar-integrate skill again\n```\n\nIf path **4.a** (Claude Code) was taken, add this line to the summary:\n\n```\n Secrets scanning: hooks registered via sonar integrate claude\n```\n\nIf path **4.b** (Copilot CLI) was taken, add this line to the summary:\n\n```\n Secrets scanning: hooks registered via sonar integrate copilot\n```\n\nIf path **4.c** (Codex) was taken, add this line to the summary:\n\n```\n Hooks & MCP: wired via sonar integrate codex\n```\n\nIf path **4.d** (Cursor) was taken, add these lines to the summary:\n\n```\n CLI integrate: wired via sonar integrate cursor\n MCP Server: enable manually in Cursor Settings → MCP (ensure a container runtime (Docker, Podman, or Nerdctl) is running; restart may be needed)\n```\n\nAnd **omit** the default `MCP Server` line (it is replaced by the Cursor-specific one above).\n\nIf path **4.e** (Antigravity) was taken, add these lines to the summary:\n\n```\n CLI integrate: wired via sonar integrate antigravity\n```\n\nIf path **4.f** (Gemini CLI) was taken, no extra line is required beyond the default MCP summary.\n\nIf **sonarqube-cli was freshly installed** in Step 1, replace the `sonarqube-cli` summary line with `sonarqube-cli: installed`.\n\nIf **`sonar self-update`** failed in Step 1, adjust the summary: omit the `sonarqube-cli` line or state that the CLI was not updated and suggest `sonar self-update` in a terminal.\n\nIf any other step failed, note it clearly and suggest the corrective action.\n"
}SHA-256: 946a10e2edbfe9c4fb572f0f21dfa0a3275277090b5b963c5ec26a3f4bf2868c